1
0
mirror of https://github.com/quay/quay.git synced 2026-01-26 06:21:37 +03:00
Commit Graph

396 Commits

Author SHA1 Message Date
jbpratt
e21a9caae2 test(web): fix service-keys tests failing due to past expiration dates (#4768)
Replace hardcoded expiration date '2025-12-31T23:59' with dynamically
generated future date. The tests were failing with "Expiration date
must be in the future" validation error since it's now 2026.

Added getFutureExpirationDate() helper that returns a date 1 year
from now in the required datetime-local format.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-02 17:21:30 -05:00
jbpratt
ef1974688e test(web): migrate more tests to playwright (#4762)
* test(web): migrate repository-shorthand-navigation to Playwright

Migrate Cypress shorthand URL navigation tests to Playwright with real
resources instead of mocked API responses. Consolidates 11 tests into 7.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate repository-permissions to Playwright

Migrate repository-permissions.cy.ts to Playwright, consolidating
6 Cypress tests into 3 Playwright tests covering:
- Inline permission display, change, and delete operations
- Bulk permission change and delete operations
- Adding permissions for robots and teams

Changes:
- Add repository permission API utilities to client.ts
- Add api.repositoryPermission() helper with auto-cleanup
- Add data-testid attributes to PermissionsToolbar and AddPermission
- Update MIGRATION.md checklist (11 migrated, 20%)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate repository-notifications to Playwright

Migrate 18 Cypress tests from repository-notifications.cy.ts to 7
consolidated Playwright tests covering notification CRUD operations,
bulk actions, and recipient field functionality.

Changes:
- Add notification API utilities to client.ts
- Add notification() method to TestApi for auto-cleanup
- Add IMAGE_EXPIRY_TRIGGER to QuayFeature type
- Add data-testid attributes to notification form components
- Create notifications.spec.ts with 7 focused tests

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate repositories-list to Playwright

Migrate repositories-list.cy.ts from Cypress to Playwright, consolidating
11 tests into 6 focused e2e tests:

- displays repositories in global and organization views
- creates repositories with different visibility and namespaces
- deletes multiple repositories via bulk action
- changes visibility for multiple repositories
- searches by name and supports regex mode
- searches by name including organization

Skipped pagination tests (test PatternFly, not app code).

Added data-testid attributes:
- CreateRepoModalTemplate: form inputs, visibility radios, buttons
- BulkDeleteModalTemplate: modal, confirmation input
- RepositoryToolBar: visibility confirmation buttons

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate robot-accounts to Playwright

Migrate robot-accounts.cy.ts from Cypress to Playwright, consolidating
12 tests into 4 focused e2e tests:

- CRUD lifecycle: create, search, toolbar, and delete robot account
- robot credentials and Kubernetes secrets
- robot repository permissions: update single permission
- robot wizard: org has 5 steps, user namespace has 3 steps

Added data-testid attributes:
- CreateRobotAccountModal: modal container
- RobotTokensModal: regenerate button, token display, docker/podman commands
- robotAccountWizard: step navigation, name/description inputs
- ExpandCollapseButton, SearchInput, ToolbarButton: pass-through testid
- RobotAccountKebab: menu items for permissions, tokens, delete
- RobotAccountsList: table container

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): remove migrated cypress tests

Signed-off-by: Brady Pratt <bpratt@redhat.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-01-02 13:37:05 -05:00
jbpratt
5a86c7a57f test(web): migrate some tests and improve framework (#4760)
* test(web): migrate logout Cypress test to Playwright

Uses unique temporary users per test to avoid session invalidation
conflicts when running in parallel. Quay's signout endpoint invalidates
all sessions for a user, which would break parallel tests sharing users.

Also documents the session-destructive test pattern in MIGRATION.md.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate mirroring Cypress test to Playwright

Migrates web/cypress/e2e/mirroring.cy.ts to Playwright following the
MIGRATION.md guide. Consolidates 18 Cypress tests into 5 Playwright
tests using real API calls instead of mocks.

Changes:
- Add mirroring API utilities to client.ts (changeRepositoryState,
  createMirrorConfig, getMirrorConfig, updateMirrorConfig,
  triggerMirrorSync, cancelMirrorSync)
- Create mirroring.spec.ts with 5 consolidated tests covering:
  - State warning and form visibility
  - New mirror configuration lifecycle
  - Existing mirror configuration management
  - Sync operations
  - Error handling (only mock used for 400 error scenario)
- Update MIGRATION.md checklist (8/54, 15%)

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): add TestApi fixture with auto-cleanup for Playwright tests

Introduce a TestApi class that wraps ApiClient and automatically tracks
created resources for cleanup after each test. This eliminates the need
for manual beforeEach/afterEach cleanup patterns and ensures resources
are always cleaned up even when tests fail.

Changes:
- Add TestApi class to fixtures.ts with methods for creating orgs,
  repos, teams, robots, and prototypes with auto-cleanup
- Add api and superuserApi fixtures that provide TestApi instances
- Migrate all committed Playwright tests to use the new api fixture
- Update MIGRATION.md with documentation for the new pattern

The api fixture provides:
- api.organization(prefix?) - creates org with unique name
- api.repository(namespace?, prefix?, visibility?) - creates repo
- api.team(orgName, prefix?, role?) - creates team
- api.robot(orgName, prefix?, description?) - creates robot
- api.prototype(orgName, role, delegate, activatingUser?) - creates default permission
- api.setMirrorState(namespace, repoName) - sets repo to MIRROR state
- api.raw - access underlying ApiClient for non-tracked operations

Resources are cleaned up in reverse order (LIFO) after each test.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): remove migrated tests

Signed-off-by: Brady Pratt <bpratt@redhat.com>

* test(web): auto-skip Playwright tests based on @feature: tags

Adds an auto-fixture to fixtures.ts that automatically skips tests
when their @feature:X tags reference disabled Quay features. This
eliminates duplication between tags and manual test.skip() calls.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(web): set axios baseURL at module level for all routes (PROJQUAY-0000)

Previously axios baseURL was only set inside StandaloneMain component,
causing requests from /signin and other auth routes to go to the wrong
URL (localhost:9000 instead of localhost:8080).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): use cy.session() for Cypress authentication

Replace manual CSRF token + loginByCSRF pattern with cy.session()
for proper session handling. Fixes race condition where React app
made API calls before Cypress login completed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): fix notification drawer test flakiness with toPass polling

Use Playwright's toPass to poll for notification appearance instead of
a single assertion. The backend may take time to process push
notifications, so reload and retry until the notification is visible.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-23 16:35:54 -06:00
jbpratt
05495a2995 test(web): migrate more tests to playwright (#4741)
* test(web): migrate notification-drawer Cypress test to Playwright

Convert the notification-drawer.cy.ts test from mocked API responses to
real API interactions. The test now creates a repository, configures a
quay_notification for repo_push events, pushes an image to trigger the
notification, then validates the drawer UI behavior (open, read, delete).

Adds createRepositoryNotification method to the Playwright API client.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate default-permissions Cypress test to Playwright

- Add robot and prototype API methods to test client
- Fix undefined allMembers bug in CreateTeamWizard.tsx
- Fix missing return value in AddTeamMember.tsx setDeletedTeamMembers
- Tests run in parallel with isolated state per test

Co-authored-by: Claude <noreply@anthropic.com>

* test(web): migrate external-scripts Cypress test to Playwright

Co-authored-by: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-17 18:51:53 -05:00
jbpratt
2c14bcadf5 fix(web): hide the overview route for on prem (PROJQUAY-0000) (#4737)
fix(web): hide the overview route for on prem

Signed-off-by: Brady Pratt <bpratt@redhat.com>
2025-12-16 11:09:11 -06:00
jbpratt
0ac8499067 test(web): consolidate Playwright API utils into ApiClient class (#4739)
* test(web): consolidate Playwright API utils into ApiClient class

Migrate from individual function-based API utilities to a unified
ApiClient class with CSRF token caching. This eliminates redundant
token requests when tests make multiple API calls.

Key changes:
- Create ApiClient class with cached CSRF token
- Add signIn() method for authentication flows
- Update all test files to use ApiClient instances
- Remove individual api/csrf.ts, organization.ts, repository.ts,
  team.ts, user.ts files in favor of single client.ts
- Update fixtures.ts to use ApiClient for login

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Brady Pratt <bpratt@redhat.com>

* test(web): run playwright on small machine for chrome only

while we are migrating, swap things around to save time and money

Signed-off-by: Brady Pratt <bpratt@redhat.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-16 14:56:43 +00:00
jbpratt
c52deaa6b3 test(web): migrate some cypress tests to playwright (#4734)
* test(web): migrate theme-switcher tests from Cypress to Playwright

Replace Cypress theme-switcher.cy.ts with Playwright equivalent.
Uses real API calls instead of mocked intercepts per migration guide.
Tests theme toggle visibility, persistence, and browser color scheme
detection via Playwright's emulateMedia API.

- Add data-testid to user-menu-toggle for stable selector
- Create playwright/e2e/ui/theme-switcher.spec.ts with 3 test cases
- Update MIGRATION.md checklist (2/54 migrated)
- Delete original Cypress test file

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate breadcrumbs tests from Cypress to Playwright

Add organization, team, and container API utilities to support the
breadcrumbs test migration. Tests cover:
- List pages (no breadcrumbs)
- Organization, repository, tag, and team page breadcrumbs
- Edge cases with same-name org/repo/team combinations

The container utility supports both podman and docker for pushing
test images when testing tag breadcrumbs.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* test(web): migrate overview tests from Cypress to Playwright

Migrates web/cypress/e2e/overview.cy.ts to Playwright with 4 tests:
- Expandable dropdowns show content
- External links navigate correctly
- Tabs switch content correctly
- Purchase plans dropdown shows pricing options

Uses getByRole for tab selection instead of PatternFly-generated IDs.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Brady Pratt <bpratt@redhat.com>

* test(ci): ignore test files for web preview

no need in deploying the web preview if only tests or docs are modified

Signed-off-by: Brady Pratt <bpratt@redhat.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-15 18:58:23 -06:00
jbpratt
69b7aff5b4 chore: add Playwright e2e test infrastructure (#4688)
* chore: add Playwright e2e test infrastructure

Add Playwright test framework with custom fixtures for authenticated
contexts, API utilities for test data management, and repository
delete test as initial migration from Cypress.

Key additions:
- global-setup.ts: Creates admin, testuser, readonly test users
- fixtures.ts: Pre-authenticated page/request fixtures by role
- utils/api.ts: CRUD utilities for repositories
- MIGRATION.md: Guide for migrating Cypress tests to Playwright
- repository-delete.spec.ts: First migrated test with full cleanup

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Brady Pratt <bpratt@redhat.com>

* chore: update web/.dockerignore

exclude tests from being included in the intermediate build - this
should improve caching when only tests change

Signed-off-by: Brady Pratt <bpratt@redhat.com>

* chore: add pre-commit check to block new cypress tests

Signed-off-by: Brady Pratt <bpratt@redhat.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-12 18:40:38 -06:00
red-hat-konflux[bot]
257078a08b chore(deps): update dependency jws to v4.0.1 (#4713)
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Co-authored-by: red-hat-konflux[bot] <126015336+red-hat-konflux[bot]@users.noreply.github.com>
2025-12-12 11:56:38 -06:00
Harish Govindarajulu
5a0d7efecd fix(ui): add label to show global readonly superuser in organizations list (PROJQUAY-9970) (#4717)
This commit adds a cyan "Global Readonly Superuser" label to identify
global readonly superusers in the Organizations list, making it easier
for administrators to distinguish them from regular superusers.

Backend change: Updated User.to_dict() to include global_readonly_super_user
property in the /api/v1/superuser/users/ API response.

Frontend changes: Propagated the property through the data flow and added
label rendering with cyan color to visually distinguish from regular
superusers (blue).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-11 14:44:28 -06:00
jbpratt
95b4ee4656 test(web): mark usage logs test as skipped due to flake (#4718)
test(web): skip flaky test

will follow up fixing it, its breaking CI all over

Signed-off-by: Brady Pratt <bpratt@redhat.com>
2025-12-11 11:30:38 -06:00
jbpratt
8593006231 fix(web): sort Build ID column numerically as hex values (PROJQUAY-9895) (#4701)
Build IDs are UUIDs displayed as hex strings. The previous localeCompare
sorting treated them lexicographically, causing incorrect sort order.
Now detects hex/UUID patterns and sorts by parsing the first 8 hex
digits numerically.

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-10 04:26:51 -06:00
jbpratt
ced2c6ffa8 feat(endpoints,web): add audit logs for quota configuration (PROJQUAY-9859) (#4692)
Adds audit logging for all quota management operations:
- org_create_quota, org_change_quota, org_delete_quota
- org_create_quota_limit, org_change_quota_limit, org_delete_quota_limit

Backend changes:
- Add LogEntryKind types in initdb.py
- Add log_action calls in namespacequota.py endpoints
- Add Alembic migration for new log kinds
- Add unit tests for audit logging

Frontend changes:
- Add log descriptions in UseLogDescriptions.tsx
- Add Cypress e2e test for quota log display

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-09 09:44:10 -06:00
jbpratt
d04f98dbcd fix(web): use template literals for Fetch Tag pull commands (PROJQUAY-9952) (#4699)
ClipboardCopy children were passed as JSX expressions which creates an
array of React nodes. PatternFly's ClipboardCopy may join array children
with commas when extracting text, causing pull commands like:
"docker pull ,hostname,/,org,/,repo,:,tag"

Using template literals ensures a single string child is passed,
preventing the comma issue.

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-09 17:29:43 +05:30
jbpratt
63bb7af32b fix(web): show error notification on org creation failure (PROJQUAY-9948) (#4691)
Use mutateAsync instead of mutate so Promise errors propagate to the
calling code. Previously, mutate() was fire-and-forget, causing success
notifications even when the API returned 400 errors.

Remove duplicate alert notification - error is shown inline in the modal.

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-08 16:58:35 +05:30
jbpratt
f4957e3e29 chore: remove deprecated reCAPTCHA support (#4690)
Remove reCAPTCHA integration from the password recovery flow
as the feature has been deprecated.

Changes:
- Delete ReCaptcha component
- Remove recaptcha token handling from Signin page
- Simplify UsePasswordRecovery hook
- Remove react-google-recaptcha dependencies
- Clean up test fixtures and CSS

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-05 08:10:43 -06:00
jbpratt
c6d948e11b fix(web): display 0.00 KiB instead of N/A for zero sizes (PROJQUAY-9860) (#4686)
The formatSize() function used a falsy check which treated 0 as invalid,
returning "N/A" instead of formatting it. Now 0 displays as "0.00 KiB"
matching the legacy UI behavior.

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-03 19:44:53 +00:00
jbpratt
ed6ebc3ff6 feat(web): show password setup prompt for OIDC users in CLI config (PROJQUAY-9898) (#4681)
when using OIDC authentication and the user has no password set, display
an info alert with a "Set password" button to guide users through setting
up their CLI password

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-03 19:05:24 +00:00
Sunandadadi
acfbf1cb6d fix(web): enable user self-service email changes when FEATURE_MAILING enabled (PROJQUAY-9879) (#4675)
* fix(web): enable user self-service email changes when FEATURE_MAILING enabled (PROJQUAY-9879)

This commit fixes the issue where users received 401 Unauthorized errors
when attempting to update their email address in the new React UI when
FEATURE_MAILING is enabled.

Root cause: ChangeEmailModal was using the superuser-only endpoint
/api/v1/superuser/users/{username}, which regular users cannot access.

Changes:
- Added useChangeEmail hook in UseCurrentUser.ts that calls the correct
  user self-service endpoint /api/v1/user/ for email updates
- Modified ChangeEmailModal to support dual modes (superuser vs user)
  with isSuperuserMode prop for backward compatibility
- Updated GeneralSettings to display email as clickable link when
  FEATURE_MAILING is enabled, opening the modal for email changes
- Pre-fill modal with current email address for better UX
- Added validation to prevent submitting the same email address
- Added 8 comprehensive Cypress e2e tests covering email change flows

The fix implements the proper email verification workflow where users
receive a verification email and must confirm before the change is applied.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* fixing tests

* resolving coderabbit suggestion

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-03 16:07:53 +00:00
jbpratt
365f88cf0b chore: remove debug css (#4669)
Signed-off-by: Brady Pratt <bpratt@redhat.com>
2025-12-02 15:16:36 +00:00
jbpratt
9337b87f0e fix(web): disable buttons for global readonly superuser (PROJQUAY-9873) (#4665)
Global readonly superusers could click Create Message and Service Key
buttons which then failed with 403 errors. These buttons are now disabled
using the existing useSuperuserPermissions hook's canModify flag.

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-02 08:22:56 -06:00
jbpratt
754196f9ac fix(web): use correct terminology in user settings panel (PROJQUAY-9884) (#4659)
The settings page showed "Organization" labels and helper text even
when viewing a user namespace. Changed to conditionally display
"Username" for users and "Organization" for organizations.

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 11:38:48 -06:00
jbpratt
0b8e74f5ac fix(web): resolve user settings log display issues (PROJQUAY-9881) (#4657)
fix(web): fix user settings log display issues (PROJQUAY-9881)

- Fix template interpolation in user_change_tag_expiration log message
- Add usageLogs query invalidation so logs refresh after settings update

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 17:21:04 +00:00
jbpratt
72d1e4f398 fix(web): show user namespace quota for non-superusers (PROJQUAY-9886) (#4658)
Normal users couldn't see their own namespace quota in the Organizations
list Size column. The backend already returns quota_report in /api/v1/user/
but the frontend wasn't using it. Added fallback to use current user's
quota_report when superuser data isn't available.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 11:11:26 -06:00
jbpratt
6bc089b61c fix(web): use correct error modal titles for different operations (PROJQUAY-9874) (#4655)
Previously, all errors on the Organizations page showed "Org deletion failed"
as the modal title, even for unrelated operations like registry size
calculation. This was confusing for Global Readonly Superusers who saw
"Org deletion failed" when trying to calculate registry size.

Changes:
- Separated error states in OrganizationsList.tsx (deletionErr, registryCalcErr)
- Added separate ErrorModal for registry calculation with correct title
- Fixed RepositoriesList.tsx ErrorModal title to "Repository deletion failed"
- Added Cypress test to verify correct error modal title

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 10:22:48 -06:00
jbpratt
37ca1eaf2d fix(web): hide Enable Team Sync when FEATURE_TEAM_SYNCING is false (PROJQUAY-9878) (#4654)
The UI was showing the "Enable OIDC Team Sync" button even when
FEATURE_TEAM_SYNCING was disabled in the config. Added check for
config?.features?.TEAM_SYNCING before displaying the team sync button.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 08:38:16 -06:00
Sunandadadi
e7988418f9 ui: ensure logout redirects to signin on network error (PROJQUAY-9792) (#4652)
fix(ui): ensure logout redirects to signin on network error (PROJQUAY-9792)

When the logout API call fails due to network error, the UI now properly
redirects to the signin page and clears the client-side session. Previously,
the user would be stuck on the current page with an error modal.

Changes:
- Move redirect and cleanup to finally block in logout handler
- Add optional chaining to user.username to prevent undefined errors
- Remove unused addDisplayError import
- Add comprehensive Cypress e2e tests for logout functionality

The finally block ensures client-side logout always succeeds, even when
the server is unreachable, improving security and user experience.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 03:18:36 -06:00
jbpratt
cdd8259c14 fix(web): load external scripts only when BILLING enabled (PROJQUAY-9803) (#4623)
Stripe and StatusPage scripts were hardcoded in index.html, causing
85-second delays in air-gapped/restricted networks as browsers waited
for connection timeouts.

Created useExternalScripts hook to dynamically load scripts only when
BILLING feature is enabled. Scripts load asynchronously to prevent
blocking page render. On-premise deployments (BILLING=false) no longer
make external requests.

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-25 22:55:10 +00:00
Brandon Caton
f57ac3f67f ui: checking field content in superuser build logs (PROJQUAY-9714) (#4640) 2025-11-25 15:19:16 -05:00
Harish Govindarajulu
36dff40df7 fix(ui): show quota consumed column for all users in organizations list (PROJQUAY-9850) (#4634)
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-25 19:37:21 +05:30
jbpratt
79f75e24b6 fix(web): display avatars for all entries in org table (PROJQUAY-9749) (#4615)
Previously only organizations and the logged-in user showed avatars.
Now all users and superusers display avatars by passing avatar data
from the API response through component props.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-25 19:36:41 +05:30
jbpratt
b4f1ef63c6 fix(web): hide Add Limit form in view-only quota pages (PROJQUAY-9845) (#4622)
Organization and user quota settings pages are view-only, but were
displaying an empty "Add Limit" form row with disabled controls.
This creates visual clutter and implies users can add limits when
they cannot.

Conditionally render the "Add Limit" card only when !isReadOnly to
match the behavior of the old Angular UI. Update Cypress tests to
verify the form does not exist (not just disabled) in view-only mode.
2025-11-25 04:17:23 -06:00
Sunandadadi
40ee3a5468 ui: prevent redirect to signin after OIDC username confirmation (PROJQUAY-9835) (#4629)
fix(web): prevent redirect to signin after OIDC username confirmation (PROJQUAY-9835)

When users authenticated via OIDC and confirmed their username, they were
incorrectly redirected back to the signin page instead of the home page.

This occurred because the OAuth flow stored the signin page URL in localStorage
as the redirect target. After username confirmation, the app would read this
stored URL and redirect back to signin, creating a loop.

The fix checks if the stored redirect URL contains '/signin' and navigates to
the home page instead.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-24 21:35:55 +00:00
Brandon Caton
4cddc368e9 ui: surfacing re-prompt for password (PROJQUAY-9844) (#4624) 2025-11-24 21:25:41 +00:00
Brandon Caton
b2141c1d60 ui: fix select during org delete bug (PROJQUAY-9843) (#4628) 2025-11-24 16:13:20 -05:00
jbpratt
f5db7ddb5b fix(web): sort Build History by timestamp instead of string (PROJQUAY-9686) (#4619)
Converts date strings to numeric timestamps for correct chronological sorting
2025-11-24 12:17:49 -06:00
jbpratt
b352135a85 fix(web): validate quota value input accepts only numbers (PROJQUAY-9837) (#4614)
* fix(web): validate quota value input accepts only numbers (PROJQUAY-9837)

Changed Storage Quota input from type="text" to type="number" to prevent
non-numeric characters from being entered. Also enhanced validation to
catch edge cases where parseFloat could incorrectly parse mixed values
like "300xxxx" as 300.

Co-authored-by: Claude <noreply@anthropic.com>

* chore: move quota test seeding

locally the test goes from 8 minutes to 55 seconds :)

Signed-off-by: Brady Pratt <bpratt@redhat.com>

---------

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-24 13:04:38 -05:00
jbpratt
bb31def220 chore: fix account settings navigation (#4607)
don't reload the page, use react router to navigate smoothly

Signed-off-by: Brady Pratt <bpratt@redhat.com>
2025-11-24 10:46:15 +05:30
jbpratt
9d0e3d29bc fix(ui): preserve mirroring credentials when updating tag pattern (PROJQUAY-9608) (#4410)
When updating mirroring configuration fields like tag patterns, credentials
were being cleared because the password field is empty by default for security.

Modified UseMirroringConfig to conditionally exclude credentials from the
update payload when the password field is empty and updating existing config.
This matches the Angular UI behavior where only changed fields are sent.

Added Cypress tests to verify credentials are preserved when updating other
fields without changing the password, and that credentials are included when
explicitly updated.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 22:57:36 +00:00
Brandon Caton
431094e244 ui: normalize user settings tabs (PROJQUAY-9814) (#4597) 2025-11-20 20:06:17 +00:00
Sunandadadi
fc913d0f18 ui: redirect new UI super user for fresh login when authentication type is OIDC (PROJQUAY-9748) (#4571)
* ui: redirect new UI super user for fresh login when authentication type is OIDC (PROJQUAY-9748)

* test(ui): Fix Cypress tests for fresh login OIDC flow (PROJQUAY-9748)

- Fixed incorrect API endpoint (/api/v1/superuser/logs* instead of /api/v1/superuserlogs**)
- Fixed incorrect route (/usage-logs instead of /superuser/usagelogs)
- Added proper authentication setup using cy.loginByCSRF
- Used fixtures (config.json, superuser.json) following existing test patterns
- Simplified tests to 3 critical cases: OIDC redirect, query param preservation, Database modal

---------

Co-authored-by: harishsurf <hgovinda@redhat.com>
2025-11-20 12:47:15 -05:00
jbpratt
c4847bc4b8 chore: add /about and /security static pages to new UI (#4592)
adds two new static information pages to the React UI:
- /about page with company info cards and bill-of-materials table
- /security page with security practices and features documentation

implementation includes:
- PatternFly components for consistent UI design
- sortable/filterable packages table with pagination
- actual CoreOS and Red Hat logos
- nginx routing configuration for new paths
- webpack config updates to handle image assets from src/assets

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 16:08:40 +00:00
Brandon Caton
aa3079b2a6 ui: adding redirect to update info page (PROJQUAY-9744) (#4579) 2025-11-20 10:41:00 -05:00
Harish Govindarajulu
770e60b942 fix(ui): Add OAuth state parameter for CSRF protection (PROJQUAY-9805) (#4562)
Implement RFC 6749 Section 10.12 compliant state parameter to prevent
CSRF attacks in OAuth token generation flow.

Changes:
- Generate cryptographically secure state using crypto.randomUUID()
- Store state in sessionStorage before OAuth redirect
- Parent window validates state from popup via postMessage
- Read state from query params (backend echoes it back)
- Display security error for invalid/missing state
- Add Cypress tests for state validation and CSRF protection

Security Impact:
- Prevents CSRF token theft and session fixation attacks
- Complies with OAuth 2.0 security best practices
- React UI only; Angular UI remains unchanged

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 15:17:18 +00:00
Brandon Caton
2bf41caba1 ui: removing feedback banner (PROJQUAY-9811) (#4577) 2025-11-20 04:29:54 -06:00
Harish Govindarajulu
129ca2ae29 fix(ui): Enable organization/user visibility for read-only superusers (PROJQUAY-6882) (#4545)
* fix(ui): Enable organization/user visibility for read-only superusers (PROJQUAY-6882)

Users listed under GLOBAL_READONLY_SUPER_USERS can now see all
organizations and users in the UI, matching regular superuser visibility
with read-only restrictions on actions.

- Update UseCurrentUser to include global_readonly_super_user in isSuperUser check
- Add Cypress tests for read-only superuser visibility and action restrictions
- Settings column actions correctly hidden via existing canModify permission

* fix(ui): Add global_readonly_super_user field to API responses (PROJQUAY-6882)

- Add global_readonly_super_user field to user API response in endpoints/api/user.py
- Allow read-only superusers to view organization teams in endpoints/api/organization.py
- Allow read-only superusers to view robot permissions in endpoints/api/robot.py

* fix(ui): Prevent read-only superusers from deleting orgs/users

Security fix: Read-only superusers should not be able to delete
orgs or users they don't own, even though they can view them.

* Fix inline import + incorrect assert + add codecov tests

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 01:31:59 -06:00
jbpratt
6160982a57 fix(web): fetch build logs from separate endpoint in superuser panel (PROJQUAY-9714) (#4493)
The superuser build logs feature was calling only
/api/v1/superuser/<build_uuid>/build which returns build metadata but
NOT logs. Logs are available from a separate
/api/v1/superuser/<build_uuid>/logs endpoint that must be called
separately.

Updated fetchBuildLogsSuperuser() to fetch both endpoints in parallel
using Promise.all and merge the results. This matches the behavior of
the old AngularJS UI which called both endpoints separately.

Updated Cypress tests to mock both API endpoints.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-19 16:07:35 -05:00
jbpratt
5de525bfa1 chore: extract logo selection logic into reusable hook (#4566)
🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: Brady Pratt <bpratt@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-19 18:38:05 +00:00
Brandon Caton
dfc4137d36 ui: allow for team creation while creating notification (PROJQUAY-9727) (#4570) 2025-11-19 12:52:53 -05:00
jbpratt
fadd126fcb fix(web): fix inline markdown code rendering (PROJQUAY-9809) (#4569)
React-markdown v10.x no longer reliably passes the inline prop to
custom code components. Changed detection to check for newlines in
code content instead, which correctly distinguishes inline code from
code blocks.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-19 17:11:41 +00:00